?
Solved

powershell command to identify when a computer account last logged onto the domain

Posted on 2014-10-01
4
Medium Priority
?
377 Views
Last Modified: 2014-10-16
Hi all,
Using powershell anyone know the command to see when a computer or server that is currently powered on last logged onto the domain.

many thanks.
0
Comment
Question by:Jason Thomas
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 12

Accepted Solution

by:
David Paris Vicente earned 1002 total points
ID: 40354435
Hi,

I used this script in the past to check what you want.
And it work great if you several DC´s

$domain = "local" 
 
################## 
#--------Main 
################## 
 
import-module activedirectory 
cls 
"The domain is " + $domain 
$samaccountname = Read-Host 'What is the User samaccountname?' 
"Processing the checks ..." 
$myForest = [System.DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest() 
$domaincontrollers = $myforest.Sites | % { $_.Servers } | Select Name 
$RealUserLastLogon = $null 
$LastusedDC = $null 
$domainsuffix = "*."+$domain 
foreach ($DomainController in $DomainControllers)  
{ 
    if ($DomainController.Name -like $domainsuffix ) 
    { 
        $UserLastlogon = Get-ADUser -Identity $samaccountname -Properties LastLogon -Server $DomainController.Name 
        if ($RealUserLastLogon -le [DateTime]::FromFileTime($UserLastlogon.LastLogon)) 
        { 
            $RealUserLastLogon = [DateTime]::FromFileTime($UserLastlogon.LastLogon) 
            $LastusedDC =  $DomainController.Name 
        } 
    } 
} 
"The last logon occured the " + $RealUserLastLogon + "" 
"It was done against " + $LastusedDC + "" 
$mesage = "............." 
$exit = Read-Host $mesage

Open in new window


Hope it helps.
0
 
LVL 1

Author Comment

by:Jason Thomas
ID: 40354848
Many thanks however I am not sure that is what I am looking for. I want to use power shell a use a command against one server at a time to see when it last logged on?
0
 
LVL 12

Assisted Solution

by:David Paris Vicente
David Paris Vicente earned 1002 total points
ID: 40354912
OK.

The script that I provided is more simple because the you will need to convert the last logon date and time to a readable state.
Get-ADUser -Identity <samAccountName> -Properties LastLogon -Server <DCName> 

Open in new window


Then the conversion.
Copy the value from Last logon and inserted inside the quotes:
[datetime]::FromFileTime("128752344000000000")

Open in new window

Both command are to be used in PowerShell

Let us know if helped
0
 
LVL 14

Assisted Solution

by:Justin Yeung
Justin Yeung earned 498 total points
ID: 40362620
$UserName = Read-Host "User SamAccountName that you are looking for"
import-module ActiveDirectory
$DCs = Get-AdDomainController -filter *
foreach ($DC in $DCs)
{

Get-ADUser -Identity $UserName -Properties LastLogon -Server $DC.Name | select Name,@{N="LastLogon";E={[datetime]::FromFileTime($_.lastlogon)}};@{N="LogonDC";E={$DC.Name}}

}

Open in new window


you can use expression directly convert the code to a readable format and doesn't need to run a 2nd command to convert it.
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Suggested Courses
Course of the Month11 days, 6 hours left to enroll

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question